NLS_PWS.docx

DOCX document 153 KB Posted

Attached to
BLS National Longitudinal Survey Recompete Federal contract opportunity
Solicitation number
1625DC-19-R-00005
Issued by
Department of Labor Bureau of Labor Statistics

About this file

NLS PWS

View the file

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

PERFORMANCE WORK STATEMENT

MANAGEMENT AND EXECUTION OF THE NATIONAL LONGITUDINAL SURVEYS

Part 1

General Information

1. BACKGROUND/HISTORY:

The Bureau of Labor Statistics (BLS) of the U.S. Department of Labor sponsors the National Longitudinal Surveys (NLS) to obtain information about how people respond to changes in the broader economy and how they make transitions through various stages of their lives. The NLS program has obtained a wealth of information about young people making the transition from school to the labor market and adulthood; individuals in their 30s, 40s, and 50s as they make choices about their careers and families; and older individuals as they prepare for and enter retirement. Such information is obtained through the National Longitudinal Survey of Youth 1979 (NLSY79), the NLSY79 Child and Young Adult Surveys, and the National Longitudinal Survey of Youth 1997 (NLSY97).

The long-term objective of the National Longitudinal Surveys is to relate individuals’ earlier development and influences on their outcomes later in life. Along the life course, information is collected on topics that influence or are influenced by labor market behavior. The content of the surveys emphasizes the behavior of individuals, but information also will be collected on aptitude and attitudes.

The NLS program is housed within the Employment Research and Program Development Staff, headed by a Senior Research Economist. Direction of the NLS program is the responsibility of the Director of National Longitudinal Surveys.

1. BACKGROUND TO THE NATIONAL LONGITUDINAL SURVEYS PROGRAM

BLS sponsors the collection and dissemination of data from the National Longitudinal Surveys. Each of these surveys has gathered information at multiple points in time on the labor market experiences, schooling, health, marital history, fertility, and other aspects of the lives of seven groups of American men and women.

In 1979, a survey was begun with a sample of 12,686 young men and women who were born in the years 1957 to 1964. The sample members were ages 14-21 as of December 31, 1978. This survey is called the National Longitudinal Survey of Youth 1979 (NLSY79). Data collection for the NLSY79 was conducted annually from 1979 to 1994 and has been conducted biennially in even-numbered years since 1994. The original sample included supplemental samples of Black or African American, Hispanic, economically disadvantaged non-Black/non-Hispanic, and youth in the military. In other words, members of these four groups composed a larger share of the total NLSY79 sample than their share of the U.S. population that was born in the years 1957 to 1964 and living in the U.S. in 1979. The reason for selecting these supplemental samples was to facilitate statistical analyses of these groups. Without these supplemental samples, the sizes of these four groups in the NLSY79 sample would not have been sufficiently large to conduct statistically reliable analyses. The military supplemental sample was discontinued after the 1984 survey, but members of the main NLSY79 sample who joined the military after the survey began in 1979 have continued to be interviewed during their military service. The economically disadvantaged non-Black/non-Hispanic supplemental sample was discontinued after the 1990 survey. The original NLSY79 sample did not include persons who were incarcerated or who resided in other types of institutions, but, to the extent possible, the survey continues to track sample members if they become incarcerated or otherwise institutionalized. Sample members who move outside the U.S. also remain eligible for interview.

In 1986, a separate survey was begun of children born to female NLSY79 respondents. In addition to the wealth of information about the mothers that is obtained from the NLSY79, the NLSY79 Child survey includes assessments of each child, as well as additional demographic and developmental information collected from either the mother or child. The NLSY79 Child survey is conducted biennially and includes a battery of cognitive, social, emotional, and physiological assessments, as well as age-appropriate questions on attitudes, aspirations, and psychological well-being. Beginning in 1994, children age 15 and older completed an interview modeled on the main NLSY79 questionnaire. These NLSY79 Young Adults are asked about their schooling, training, work experiences and expectations, health, dating, fertility, marital histories, and household composition. A confidential questionnaire records their reports on such topics as parent-child conflict, participation in delinquent or criminal activities, use of controlled and uncontrolled substances, and expectations for the future.

In 1997, the newest NLS cohort was begun with the collection of data from a sample of approximately 9,000 youths who were born in the years 1980 to 1984. The sample members were ages 12-16 as of December 31, 1996. This survey, called the National Longitudinal Survey of Youth 1997 (NLSY97), is fielded biennially and includes supplemental samples of Black or African American and Hispanic youths. The original NLSY97 sample did not include persons who were incarcerated or who resided in other types of institutions, but, to the extent possible, the survey continues to track sample member if they become incarcerated or otherwise institutionalized. Likewise, the survey continues to track sample members who join the military. Sample members who move outside the U.S. also remain eligible for interview.

NLS data are used by economists, sociologists, and other researchers in government, the academic community, and private organizations to examine a variety of issues such as: employment and earnings of workers; educational experience, achievement, and the transition from school to work; training programs and training in the workplace; geographic mobility; relationships between the workplace and the well-being of the family and family transitions; drug and alcohol use; juvenile delinquency and criminal behavior; fertility and childbearing, especially the problems of adolescent fertility on both the mothers and their children; and preparations for retirement, with an emphasis on income, assets, and family structure.

NLS Sample Retention In recent rounds, the NLSY79 and the NLSY97 have maintained retentions rates of approximately 78 percent of eligible respondents.

NLS Content Respondents in all NLS cohorts (except the NLSY79 Child) have been asked a core set of questions that provide information on employment, training, work experience, sources of income, marital status, health, attitudes toward work, and occupational and geographical mobility. In addition, each cohort is asked questions that are of particular research interest for that cohort.

The focus of each survey in the NLS program has been determined by the particular stage of life that each cohort was experiencing. For example, the focus of the Older Men was on their plans for the future— specifically, retirement, pension plans, and health insurance. Special topics for the Mature Women included volunteer work, household activities, retirement plans, childcare, parental care, health insurance, commuting time and costs, attitudes toward working women, and perceived job discrimination. The surveys of the Young Men’s and Young Women’s cohorts focused on educational goals, high school and college experiences, and future job plans. In addition, surveys of the Young Men collected information on military service and union membership, while special topics for the Young Women included fertility, childcare, responsibility for household tasks, attitudes toward working women, and perceived job discrimination.

The NLSY79 included questions in the initial survey year of 1979 about the respondents’ family background, knowledge of the world of work, the influence of significant people in their lives, and the amount of control respondents feel they have over their lives and jobs. Subsequent rounds of the NLSY79 have included questions on employment and job changes, job-search methods, earnings, employee benefits, income, assets, health, fertility, marital and other relationships, migration, attitudes toward work, educational and occupational aspirations and expectations, school discipline, self-esteem, childcare, drug and alcohol use, delinquency, and time use. Whenever possible, new questions follow the language and format of questions that have been developed from other surveys to achieve comparability across surveys. NLSY79 respondents have been the subject of a number of special studies. The most notable are the Profile of American Youth, a high school transcript study, and child assessments. The Profile of American Youth, sponsored by the U.S. Department of Defense, involved the administration of the Armed Services Vocational Aptitude Battery (ASVAB) to 94 percent of NLSY79 respondents. The purpose was to obtain data on vocational aptitudes of youths and to update national norms for the ASVAB. The high school transcript study, sponsored by the National Center for Research in Vocational Education, obtained information on school characteristics and complete high school records for many of the civilian respondents. The National Institute of Child Health and Human Development provides funding to BLS to conduct the child assessments that have been administered to the biological children of female NLSY79 respondents in even-numbered years starting in 1986. These assessments encompass cognitive, socio- emotional, and physiological aspects of development, as well as information about the home environment.

The NLSY97 completed its first round in 1998. In the early rounds of interviews, the NLSY97 has been designed to document the transition from school to work and into adulthood. This survey collects extensive information about the youths’ labor market behavior and educational experiences over time. Employment data include start and stop dates of jobs, occupation, industry, hours, earnings, benefits, and job-search methods. Measures of work experience, tenure with an employer, and employer transitions also are obtained. Educational data include youths’ schooling history, performance on standardized tests, course of study, the timing and types of degrees, and a detailed account of progression through post-secondary schooling.

In addition to educational and labor market experiences, the NLSY97 obtains detailed information on many other topics. Subject areas include youths’ relationships with parents, contact with absent parents, marital and fertility histories, dating, sexual activity, onset of puberty, training, participation in government assistance programs, expectations, time use, criminal behavior, and alcohol and drug use. Areas of the survey that are potentially sensitive, such as sexual activity and criminal behavior, comprise the self- administered portion of the interview. In 1997 and 1998, NLSY97 respondents were administered the computer-adaptive version of the Armed Services Vocational Aptitude Battery, which comprises 12 tests that measure knowledge and skill in a number of areas including mathematics and language. High school transcripts have been collected and coded for most respondents. Surveys have been conducted in 1996 and 2000 of the high schools located in the areas where NLSY97 respondents reside.

Round 1 of the NLSY97 included a parent interview that generates information about each youth’s family background. Information in the parent questionnaire includes parents’ marital and employment histories, relationship with a spouse or partner, ethnic and religious background, health (parents and child), household income and assets, participation in government assistance programs, youths’ early childcare arrangements, child custody arrangements, and the parent’s expectations about the youth. Although the parent interview was only conducted in the first round, subsequent rounds asked a parent or guardian a small number of questions about family income.

Features of the NLS

The NLSY79 and NLSY97 have several features that make them exceptional resources for labor market analyses. Three features of particular importance are the breadth of information collected, the event history format (that is, the notation of the dates of significant life events), and the high retention rates. The surveys collect a vast amount of labor market information, accompanied by complementary variables which affect work and life decisions. The surveys collect detailed information about each job held, along with the characteristics of that job, including wages, hours, occupation, and industry. Each period of nonwork is investigated to capture time spent looking for work and other factors that distinguish the unemployed from those not in the labor force. Detailed information is collected on education and training, as well as events such as marriage, divorce, and fertility, which affect labor market choices.

The NLS program is funded principally by BLS, but other government agencies also provide funding for specific program activities. The National Institute of Child Health and Human Development (NICHD) provides funding to conduct the NLSY79 Child and Young Adult surveys. The National Institute on Drug Abuse has provided funding to include questions in the NLSY79 and NLSY79 Young Adult survey about the use of drugs and other substances. NICHD has provided funding to include questions in the NLSY97 on fertility, sexual activity, health-related behaviors, marriages, and relationships with parents. Early rounds of the NLSY97 included questions funded by the Department of Justice on criminal activities. The Department of Education provided funding for questions in the NLSY97 that pertain to participation in school-to-work programs. The Department of Education also provided funding to collect and code the high school transcripts of NLSY97 respondents and to administer the 1996 and 2000 surveys of high schools.

1.1 SCOPE AND DESCRIPTION OF SERVICES: The contractor shall provide non-personal services for management and execution of the National Longitudinal Survey of Youth 1979 and the National Longitudinal Survey of Youth 1997, and for management and execution of the National Longitudinal Survey of Youth 1979 Child / Young Adult, as defined in this Performance Work Statement except for those items specified as government furnished property and services. The contractor shall perform to the standards in this contract.

Task 1: Management (BASE CLIN 0001) The Contractor shall manage the collection in an efficient manner that fosters communication with contractor staff, the NLS Contract Officer’s Representative (COR), the Department’s Contracting Officer (CO), the Department’s Contracting Specialist (CS), the NLS project staff, and data users.

1.1.0 Management and Staffing Plan

The Contractor shall submit for approval of the COR a detailed management and staffing plan that will ensure the effective accomplishment of all NLS tasks. The plan shall focus on how the Contractor will hire, train, and maintain staff, manage day-to-day survey operations, and coordinate activities to prevent problems and bottlenecks and resolve problems as they occur. The plan also shall include a detailed timeline for all activities that will take place over the course of this contract. The timeline shall include the dates of each milestone and describe the dependency relationships between various activities. Approval of the plan will depend on whether it provides for qualified staff and the efficient, effective training of all Contractor staff in the project’s objectives and the administration of the surveys.

Deliverables, Timing, and Submission

1.1.1 Management and Staffing Plan

The Contractor shall submit the management and staffing plan 45 business days after the effective date of this contract. Management and staffing of the field interviewers and managers shall be addressed in Survey Procedures Plan.

1.2.0 Electronic Document Management System (EDMS)

The contractor shall develop and maintain an electronic document repository. The contractor shall update the repository and routinely produce information about all contract activities including project schedules, minutes for all meetings, contact information for project staff, organization charts, instruments, testing protocols, quality control procedures, training materials, Office of Management and Budget (OMB) documents/materials, Technical Review Committee documents/materials, daily data collection reports (during data collections), invoices, and all deliverables (without sensitive personally identifiable or respondent information). The contractor shall provide access to this information to the survey staff, the CO, and the COR on an on-going, as-needed basis. The EDMS will provide storage, versioning, as well as indexing and retrieval capabilities.

Deliverables, Timing, and Submission

1.2.1 Document Management Plan

Within 45 days of contract award, the contractor shall deliver a plan detailing the essential documents, irrespective of format, that they produce during the scope of the contract and where these will be placed in the electronic storage system. This plan will be updated as needed.

1.2.2 Document Management Repository

The EDMS shall be updated according to the approved Document Archive Plan throughout the life of the contract. A list of documents added to the archive will be submitted monthly. All documents in the Document Archive Plan generated during the life of the project will be stored. The archive shall identify file name, dates, and key words associated with each document. The contractor shall deliver each round specific archive to NLS/BLS at the end of each data round in a FIPS 140-2 compliant manner.

1.2.3 Final Transfer of All Documents in the EDMS

Upon expiration or termination of the Contract, Contractor follow the Agency’s direction as to the preservation, transfer, or destruction of Agency Data including documents stored in the document archive. Upon request by the Agency, Contractor shall certify in writing that preservation, transfer and/or destruction of documents has been completed.

1.3.0 Records Management

Records management plays a critical role in transparency and open government consistent with law and policy, to disclose information rapidly in forms that the public can readily find and use. This includes records created by the NLS program, the secure storage, maintenance, and accountability of these records, and the proper use and final disposition of these records.

1. Contractor shall comply with all applicable records management laws and regulations, as well as National Archives and Records Administration (NARA) records policies, including but not limited to the Federal Records Act (44 U.S.C. chs. 21, 29, 31, 33), NARA regulations at 36 CFR Chapter XII Subchapter B, and those policies associated with the safeguarding of records covered by the Privacy Act of 1974 (5 U.S.C. 552a). These policies include the preservation of all records, regardless of form or characteristics, mode of transmission, or state of completion.

2. In accordance with 36 CFR 1222.32, all data created for Government use and delivered to, or falling under the legal control of, the Government are Federal records subject to the provisions of 44 U.S.C. chapters 21, 29, 31, and 33, the Freedom of Information Act (FOIA) (5 U.S.C. 552), as amended, and the Privacy Act of 1974 (5 U.S.C. 552a), as amended and must be managed and scheduled for disposition only as permitted by statute or regulation.

3. In accordance with 36 CFR 1222.32, Contractor shall maintain all records created for Government use or created in the course of performing the contract and/or delivered to, or under the legal control of the Government and must be managed in accordance with Federal law. Electronic records and associated metadata must be accompanied by sufficient technical documentation to permit understanding and use of the records and data.

4. NLS Program Office records management is aligned with the 36 CFR 1220.324 which is to ensure agencies must create and maintain authentic, reliable, and usable records and ensure that they remain so for the length of their authorized retention period. The NLS follows Statistical Programs Bucket Schedule N1-257-11-1, which was approved by NARA on January 29, 2013. The National Archives and Records Administration (NARA) provides mandatory instructions on how and when to maintain and dispose of operational

1.3.1 Records Retention Documentation of Contractor Survey Methodology Files Survey Methodology Records include procedural manuals, technical memorandums, all data collectors’ training materials for both Field Managers and Field Interviewers, and communication related to survey issues (such as discussions about sample representativeness, interview sample priorities etc) and all contractor discussions with PIs

1.3.2 Records Retention Documentation of Contractor Program Subject Files Records Retention Records include correspondence (??), internal memos, drafts, planning documents, task force reports, internal explanatory statements (regarding objectives, strategy, and methodology), progress reports, documentation related to procedural problems and recommendations, study reports or other methodological or analytical statements used in reviewing or revising procedures or operational processes during revision cycles, weighting plans, created variable plans, geocode plans

1.3.4 Records Retention of Permanent Output Database Files

Master Database documentation includes the full public use data set without PII, in asci, with associated programs to read said asci data set;, in datasets by survey round. NLS Users guides in electronic form, data codebooks

1.3.5 Records Retention of Outside Committees

Documentation includes but is not limited to agendas, minutes, presentations, and reports as well as related records created by or documenting accomplishments. This includes Outside Committees: List of candidates, Letters of invitation, Agenda and advance materials, and summary of discussion and recommendations of meeting to be sent to committee members

Deliverables, Timing, and Submission

1.3.0.1 Submission of Contractor Records

Records will be submitted in electronic form 14 months after the end of data collection upon release of the public use dataset in a FIPS 140-2 compliant manner.

1.4.0 Monthly Progress Report

Although monthly reports shall be used to document problems encountered in addition to proposed solutions, the Contractor shall not wait to communicate problems to the COR in the monthly report. The Contractor shall inform the COR of challenges being faced on a flow basis as challenges arise.

Deliverables, Timing, and Submission

1.4.1 Monthly Progress Report

The monthly report shall be submitted by electronic transmission. It shall be due on the 5th day each month (or next business day if the date occurs on a weekend or Federal holiday).

1.5.0 Management Conference Calls

The Contractor shall prepare for and participate in conference calls with the NLS Director, COR and other BLS staff on a regular basis to discuss survey operations. These calls may occur every one to two weeks as needed and agreed upon by the COR and Contractor. The Contractor can expect a typical call to last one hour or less. The Contractor shall propose a written agenda for each call, subject to the approval of the NLS Director.

Deliverables, Timing, and Submission

1.5.1 Meeting Agenda

The Contractor shall distribute the agenda and all supporting materials to call participants at least one work day prior to the meeting.

1.5.2 Meeting Minutes

The Contractor shall distribute the minutes of the prior conference call with the agenda for the next call.

Task 2: Information Technology Security Requirements for BLS Data and Systems (BASE CLIN 0002) The contractor shall enforce strict procedures for assuring data confidentiality and security. These procedures shall apply to all phases of the project and should include but not be limited to: information used to locate study respondents, data collection in the field, coding and editing phases of data prior to machine processing, safeguarding response documents, and maintenance of any respondent follow-up information.

The contractor shall physically separate the identifying data required for any respondent follow-up from data required for research purposes.

2.1.0 Confidential Information Protection and Statistical efficiency Act (CIPSEA)

BLS assures participating individuals that any data collected is protected in accordance with the Confidential Information Protection and Statistical Efficiency Act (CIPSEA), the Privacy Act, and other applicable Federal Laws.

Due to the possible exposure to data protected by law under CIPSEA, the BLS shall, in accordance with this contract, designate Contractor employees with exposure to NLS data as agents of the BLS. All such agents are subject to the fines and penalties under Section 3572 of CIPSEA and any other fines and penalties that apply to the mishandling of confidential information.

The Contractor shall provide the contract employees with instructions on maintaining the security of all confidential information in accordance with this contract and applicable requirements outlined in the Attachment/Appendix X titled “BLS Confidentiality Requirements”. Such instructions are subject to the review and approval of the BLS upon request.

Deliverables Timing and Submission:

2.1.1 Potential BLS Agent List:

Within 30 day of contract award, the Contractor will furnish to the BLS a list of Contractor employees who the Contractor believes require access to BLS confidential information in order to perform work on the contract. Under this contract, all contract employees must become BLS Agents and take BLS confidentiality training before accessing BLS confidential data. This list must be updated as new employees begin work on the contract

2.1.2 Annual Training recertification:

For the life of the contract, all BLS agents currently working this contract during the recertification period will take confidentiality training at least once a year. This annual recertification will begin in the summer and end by September.

2.1.3 BLS Agent Status Worksheet:

The Contractor will keep records on current Agent designations and will report such information promptly to the COR upon request, but at least Quarterly. BLS will provide an excel worksheet for this process.

2.1.4 Location list:

Within 30 days of the contract award, the Contractor must provide the COR a list of all worksites for approval at the start of work provided for in this contract and subsequent task orders. During the duration of the contract, the contractor must notify the COR in writing of any proposed changes (additions or deletions) to the list of worksites.

2.2.0 Compliance with Federal, Department, and agency Policies The Federal Information Security Modernization Act of 2014 (FISMA) tasked the National Institute of Standards and Technology (NIST) with providing minimum security requirements for the protection of sensitive information while residing in nonfederal information systems. The Contractor agrees to ensure that all Contractor-owned systems used to store or process data under this agreement comply with all applicable information security directives, acts, laws, regulations, standards, and guidelines. The contractor shall implement any revisions to the requirements described below, within one year of release, or other timeframe as indicated by the COR, and at no additional cost to the government. In instances where the Contractor finds that a security control does not apply, the Contractor may request an exception. Any exceptions must be approved in writing by the BLS.

1. To ensure that security controls for all DOL/BLS information systems are properly selected, authorized, implemented and maintained in compliance with Federal requirements, the Contractor and all sub-contractors shall comply with the DOL/BLS IT security policy requirements, per the following documents. Aside from NIST 800-53, these documents contain restricted access data and are therefore considered confidential and will be made available to the Contractor selected.

a) NIST Special Publication 800-53, “Security and Privacy Controls for Federal Information Systems and Organizations.”

The Contractor shall ensure implementation of the respective security controls catalogued in the current version of NIST 800-53 for a “Moderate” baseline system. These controls shall be subject to assessment and testing guidance provided in NIST Special Publication 800-53A, “Assessing Security and Privacy Controls in Federal Information Systems and Organizations.” Per NIST 800-53, BLS reserves the right to request the system security plan at any time and any associated plans of action for any planned implementation or mitigations. In instances where the Contractor finds that a security control does not apply, the Contractor may request an exception. Any exceptions must be approved in writing by the BLS.

b) The DOL Computer Security Handbook (DOL CSH) The CSH, which is largely based on NIST 800-53, provides policies and procedures that establish uniform policies, authorities, responsibilities, and compliance for system security planning in accordance with NIST standards and other Federal requirements. The CSH also defines Department-specific security control parameters and includes additional guidance on incorporating Federal security standards into information systems owned or operated on behalf of the Department of Labor. The provisions of DOL policies pertain to all DOL/BLS information systems.

c) Bureau of Labor Statistics IT Security Manual (ITSM) The purpose of the ITSM, which is also based on 800-53, is to protect BLS assets through the promotion of appropriate security controls. This manual outlines a comprehensive, optimum set of security controls, discussing specific policies and responsibilities, including agency-specific security parameters.

2. The Contractor shall maintain the confidentiality, integrity, and availability of all Bureau of Labor Statistics (BLS) data and systems and their associated hardware, software, and processing capabilities. The Contractor shall develop and implement a security program in consultation with the COR, and designate security point of contact, to fulfill all security requirements under this contract. The security program shall include but is not limited to the following activities,:

a) Maintain the designated level of security compliance.

b) Develop, implement, and maintain security policies and procedures for security of facilities, computer systems, telecommunications/Internet connectivity, data, personnel, and system administration.

c) Enforce security controls on and during the system design, system testing, system implementation, system maintenance, and system disposal.

d) Control physical and logical access.

e) Document and correct or mitigate all security defects and deficiencies.

f) Inform all subcontractors that the subcontractors are also required to meet the security requirements described herein.

g) Support Government-sponsored Security Compliance Reviews, security inspections, tests, assessments, audits, and evaluations.

3. All periodic reports and updates regarding the NLS system are coordinated by BLS staff, but the NLS Contractor and its subcontractors are expected to contribute all pertinent information about the security of the NLS system components under the management and control of the Contractor or subcontractors. The periodic reports that are currently required include those listed below. This list is subject to change during the life of the NLS contract depending on any changes to Federal legislation, policies, guidelines, and standards.

4. The Contractor shall update security documents in the event of any major system changes, incident reports, newly discovered vulnerabilities, or weakness mitigations. The Contractor shall produce additional security documentation consistent with NIST 800-53 standards upon request by the COR at no additional cost to the government

2.2.1 NLS System Assessment and Authorization

Department of Labor policies require Assessment and Authorization (A&A) of all information systems that process sensitive information. The A&A process ensures that the system owner documents all of the known security risks inherent in operating a system and obtains approval from the BLS leadership to operate that system with those known risks and any mitigation plans to reduce the risks. The Department developed the A&A policies and procedures to ensure controls are properly implemented and maintained. A federal information system is an information system used or operated by an executive agency, by a contractor of an executive agency, or by another organization on behalf of an executive agency.

Authorization is the process developed to promote a better understanding of agency-related mission risks resulting from the operation of information systems. In order to ensure that proper measures have been taken to secure federal information systems, BLS senior management is required to accredit the processing of each information system prior to placing the system into operational phase. An Authorization decision is valid for a period of up to three years or until a significant change occurs to the system. During the Authorization period, however, additional tasks must be performed to ensure that the conditions underlying the Authorization do not change. These tasks include the continuous monitoring of security controls, regular security assessment, and completion of security documents as required. By performing these tasks, BLS senior management can maintain reasonable confidence that the information resources are properly protected and are able to meet the mission of the agency.

The NLS Contractor is expected to assist BLS staff in preparing documentation for the A&A process. The Contractor also is expected to monitor security controls continuously and to assess system security periodically to identify and mitigate risks. The most recent A&A for the NLS system was completed in June 2017. The renewal of the A&A for the NLS system will occur in 2020. The Contractor that is awarded the NLS contract under this Request for Proposal will be expected to assist in the A&A process conducted for the NLS system in 2020.

Deliverables Timing and Submission:

2.2.1.1 NLS System Assessment and Authorization (Initial ATO If needed) If the NLS system does not already have a signed Authority to Operate (ATO), within 6 months of contract award the contractor based NLS system will undergo the full Assessment and Authorization process and the BLS Agency Head must approve its operation. This must be completed before any data can be placed in the system

2.2.1.2 NLS System Assessment and Authorization (every three years) The NLS system, however, must be authorized to operate before data can be moved into the system. If needed, within 6 months of contract award, the contractor based NLS system will undergo the full Assessment and Authorization process and the BLS Agency Head must approve its operation.

2.2.2 Security Self-Assessment

The Security Self-Assessment (SSA) as required by NLS is conducted annually. The NLS Contractor and subcontractors are expected to assess mandatory managerial, operational, and technical elements. The NLS Contractor and subcontractors are expected to cooperate with BLS staff to coordinate interview schedules; provide applicable documentation or copies; and set up time for observation of applications to demonstrate application functions and controls. The Contractor shall support security inspections conducted by Government auditors or other Government representatives, as designated by the BLS, at no additional cost. The Contractor shall permit security inspections of its approved worksites, system configuration, and operating environment to ensure a secure operation and protection of Federal information processed by any system or operation supporting BLS data collection or processing

Deliverables Timing and Submission:

2.2.1.2 NLS Partial System Security Self-Assessment, Annual

2.2.3 Full NIST Security Controls Assessment (every 3 years)

The Security Controls Assessment (SCA) is conducted every three years as part of the A&A process described above. Staff from BLS or a third-party contractor will assess the managerial, operational, and technical elements deemed by the COR as elements needed in the NLS system. This assessment will involve analysis of the NLS system’s software, hardware, and communication controls. The NLS Contractor and subcontractors are expected to cooperate with the Security Controls Assessment team to coordinate interview schedules; provide applicable documentation or copies; and set up time for observation of applications to demonstrate application functions and controls.

Deliverables Timing and Submission:

2.2.1.3 NLS Independent Full System Audit, Every three years

Contractor will fully assist an outside auditor to complete a full FISMA audit of all applicable NIST 800-53 controls

2.2.4 Plan of Action and Milestones (Ongoing)

The Contractor shall document the Contractor’s efforts in identifying, assessing, prioritizing, and monitoring the progress of security efforts, vulnerabilities, and corrective actions for fixing or mitigating security weaknesses found in operations, or operating environments of any systems involved in storing, processing, or collecting BLS data. This information should be recorded in the form of a Plan of Action and Milestones (POA&M), and should be updated when a security weakness is found on the NLS system. The POA&M describes a weakness and the steps planned for resolving or mitigating the weakness. Each step also includes a planned completion date. The Contractor shall promptly report defects or deficiencies to appropriate supervisory and/or security personnel for follow-up action. For a weakness to be resolved and removed from the POA&M, the NLS program must provide evidence demonstrating the resolution of the weakness.

The POA&M should be accompanied by a security progress report that demonstrates that the Contractor has reviewed the audit trail, listed major security issues highlighted in the review of the audit log, and described the Contractor’s action(s) on those security issues.

The Contractor shall report the estimated cost incurred by the Contractor for all security-related activity for the quarter. Estimated security costs shall include labor expended on security deliverables and labor and other direct costs expended on design, development, and testing of the security features of the system design. The security cost report shall include the dollar amounts budgeted for the reported security expenditures. The security cost report shall be provided in the security progress report.

Deliverables Timing and Submission:

2.2.4.1 Plan of Action and Milestones (Ongoing)

Templates and instructions for documenting POA&Ms will be provided to the Contractor by the NLS ISSO. POA&Ms will be continually monitored, with progress updates required quarterly.

2.2.5 System Security Plan

The Contractor shall develop and document a formal plan detailing the security policies, procedures, and controls required for any systems involved in storing, processing, or collecting BLS data, as required. The System Security Plan (SSP) shall be completed and submitted to the NLS ISSO within the first quarter following the contract award. The SSP shall be updated annually or upon major changes to the system or system environment. The SSP shall address all management, operational, and technical controls specified in NIST Special Publication 800-53, Recommended Security Controls for Federal Information Systems: Minimum Security Controls, Moderate Baseline. The Contractor shall implement all security controls as prescribed by NIST, and shall report to and seek approval from the BLS for any deviations from NIST 800-53. To provide assurance that the implemented controls are operating as intended, the Contractor shall follow NIST SP 800-53A, Guide for Assessing the Security Controls in Federal Information Systems.

The purpose of System Security Plan (SSP) is to ensure controls are properly selected, authorized, implemented, and maintained in accordance with NIST standards. The SSP lists all controls for the NLS system and specifies their implementation status.

Deliverables Timing and Submission:

2.2.5.1 The System Security Plan (SSP)

The SSP shall be completed and submitted to the NLS ISSO within the first quarter following the contract award. The SSP shall be updated annually or upon major changes to the system or system environment.

2.2.6 Configuration Management Plan

A Configuration Management (CM) plan must be established, documented, maintained, and applied to the NLS system. The appropriate hardware, software, and procedural configuration mechanisms must be defined and developed during the Planning & Requirements Definition Phase of the system development life cycle, and updated and maintained throughout the remaining life cycle phases for the system. The information system personnel and information system must develop a baseline configuration and inventory, control and monitor configuration changes, enforce access restrictions and least functionality, and configure security settings.

Deliverables Timing and Submission:

2.2.6.1 The CM plan must be updated at least annually,

2.2.7 Business Impact Analysis

The BIA is designed to characterize the system components, supported mission/business processes and functions, and note interdependencies. Based on this information, the agency must characterize the consequences of a disruption or system unavailability. As part of the contingency planning process, a BIA is developed to identify and prioritize system components as they correlate to the mission/business process(s) and essential function(s).

Deliverables Timing and Submission:

2.2.7.1 The Business Impact Analysis must be updated least annually,

2.2.8. Contingency Plan and Testing

Contingency planning ensures that an information system can recover from processing disruptions, regardless of the source of the disruption. The Contractor shall develop a contingency planning program in accordance with NIST SP 800-34, Contingency Planning Guide for Information Technology Systems.

Contingency planning documentation consists of two deliverables: Contingency Plan (CP) and CP Test Report.

i. The CP shall include step-by-step procedures to be followed in the case of a major or minor disruption to normal operations. The Contractor shall develop a CP that can be used to ensure that any systems involved in storing, processing, or collecting BLS data can continue to operate and perform its function, as needed, during and after any processing disruption, localized emergency, or large-scale disaster. The CP shall provide detailed procedures in the cases for loss of single files, loss of machines, and loss of the entire system.

The CP shall be completed and submitted to the NLS ISSO within the first quarter following the contract award. The CP shall be updated annually or upon major changes to the system or system environment. The CP shall be maintained in a state of current operational readiness to ensure continuity of support if events occur that prohibit normal operations. Current operational readiness means that the Contractor shall perform necessary reviews and updates to keep the CP current. The Contractor may develop separate documents that, combined, provide the information required in the CP. A hardcopy of the combined and complete CP shall be maintained at both the primary contract site and at an off-site location.

The Contractor shall conduct annual notification tests, and biannual technical and tabletop CP tests as required. The Contractor shall analyze test results, report to the NLS ISSO annually on the results of these tests in a CP Test Report, and subsequently modify the CP, as appropriate. The Contractor shall present sufficient documentation and evidence of action in the CP Test Report to validate the findings presented. The test report shall include details on what elements of the CP and CP Test Plan did and did not work properly.

The Contingency Plan contains the NLS program’s detailed plans for responding to an incident that renders an information technology system partially or completely inoperable. The contingency plan is the repository for the NLS system’s business continuity and disaster recovery information, tasks, and procedures to be used when responding to interruptions of normal business operations and services.

ii. Additionally, the contingency plan must be tested and updated annually. Annual reviews must be conducted, and records of these reviews must be included with the Contingency Plan.

Deliverables Timing and Submission:

2.2.8.1 Contingency plan: updated at least annually

2.2.8.2 Contingency plan testing: Will be completed at least annually

2.2.9 Incident Response Plan

The Incident Response (IR) Plan contains detailed information on how security incidents are handled, tracked, monitored, and reported. Annual reviews must be conducted. The Contractor shall conduct annual tests as required. The Contractor shall analyze test results, report to the NLS ISSO annually on the results of these tests in an IR Test Report, and subsequently modify the IR Plan, as appropriate. The Contractor shall present sufficient documentation and evidence of action in the IR Test Report to validate the findings presented. The test report shall include details on what elements of the IR Plan and IR Test Plan did and did not work properly

Deliverables Timing and Submission:

2.2.9.1 Incident Response Plan (Updated at least annually)

2.3.0 Information Technology Security Requirements for BLS Data and Systems

The confidentiality of individually identifiable information contained in project documents, data, and other information supplied by the National Longitudinal Surveys Program, Bureau of Labor Statistics, U.S. Department of Labor, or information acquired in the course of this contract must be maintained, secured, and protected from disclosure as provided. The Contractor shall maintain the confidentiality, integrity, and availability of all Bureau of Labor Statistics (BLS) data and systems and their associated hardware, software, and processing capabilities. The Contractor shall develop and implement a security program, as approved by the COR, and designate an information security point of contact, to fulfill all security requirements under this contract.

1. The Contractor agrees not to access the NLS system remotely. Exceptions to this provision are dependent upon the submission and BLS approval of a detailed plan that incorporates all security requirements. Specifically, the contractor must submit a compelling operational need for remote access that utilizes BLS- and NIST-approved encryption standards on Contractor-owned and -maintained computer equipment. Approval of the Contractor’s remote access plan is at the sole discretion of the BLS and must be received in writing by the COR before any such access can take place. If approval is granted by the BLS, the Contractor will forward to the COR the name of each employee that it intends to access the NLS system, the primary work function(s) of the employee, whether the employee will have remote access to confidential information, the planned frequency of remote access, the location(s) from which the employee will access the NLS system remotely, and whether the employee has administrative access rights (onsite or offsite) to the Contractor equipment. The BLS must approve each employee’s remote access arrangement or any revisions to such arrangements prior to any remote access by the employee. The Contractor and the NLS Information System Security Officer (ISSO) will both maintain a list of all approved remote access arrangements that will include, at least, the information stated above and the date the COR approved the arrangement. The BLS retains the right to revoke any approved remote access for any employee or employees at any time without cause.

2. BLS reserves the right to review and approve or disapprove any security safeguards instituted to comply with the requirements of this contract. BLS also reserves the right on behalf of itself and the Government to conduct confidentiality and security compliance reviews as deemed appropriate to ensure compliance with all security policies and directives, including unannounced security inspections of the Contractor's facilities and approved worksites. Reviews may involve inspection of the facilities, technical capabilities, documentation, records, databases, operations, and procedures provided for the performance of any work under this contract. The Contractor shall support security inspections conducted by Government auditors or other Government representatives, as designated by the COR. BLS data physically and/or electronically maintained at the Contractor’s worksites will be sufficiently segregated from any other confidential data the Contractor maintains in order to facilitate BLS security inspections. No other obligations on the part of the Contractor may restrict BLS access to Contractor facilities where BLS confidential information is maintained. The Contractor may not put forth legal qualifications for, or in any way restrict, BLS access to these systems or facilities for the purpose of determining compliance with contract requirement. On the basis of such security inspections, the COR may require specific measures in cases where the Contractor is found to be non-compliant with contract requirements.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it.